Cookie notice
Last updated: 15 September 2026 (Version 1.2)
Ordinary invited sign-in uses two essential cookies. We do not use advertising or analytics cookies in this service.
- __Host-hyfid-identity-browser binds sign-in to your browser and helps prevent forged requests. It lasts up to one hour and is renewed when you visit the home page.
- __Host-hyfid-identity-session identifies your signed-in session. It lasts up to one hour after sign-in and is not extended by returning to the page. A service restart may end the session sooner.
These cookies contain random identifiers, rather than your email or provider password. They are restricted to this service's host and secure connections and cannot be read by page scripts.
Disconnecting and signing out clears both cookies. Visiting the home page again creates the browser cookie. You can also delete or block cookies in your browser, but sign-in will not work without them.
Prolific study
The Prolific organisation-account study uses the browser-binding cookie above and __Host-hyfid-identity-research, an essential cookie that links this browser to your study attempt and result. The study cookie lasts up to 24 hours and contains a random reference, not your organisation email address, Prolific ID or provider tokens. It has the same host, secure-connection and script-access restrictions as the sign-in cookies. The study does not create the signed-in session cookie.
The study cookie can remain after you finish so you can return to the result. It does not extend retention of your full email or OAuth tokens. You can remove it through your browser settings; blocking or removing it may prevent us from linking the attempt to your browser. The Consumer Privacy Notice explains the separate retention of study records.
Microsoft and Google manage cookies on their own sign-in pages under their own notices. For questions about hyf.id cookies, contact privacy@hyf.id. Our privacy notice explains the associated information and your rights.